Application Security Analyst

16 Sep 2026
Apply

Shape and strengthen application security across Rest, one of Australia's largest profit-to-member super fundsDrive secure-by-design practices across modern cloud, API and DevSecOps environmentsPartner with engineering, architecture and product teams to improve security outcomes at scaleSydney or Melbourne Located - Hybrid Working - Blend of CBD Office and Remote At Rest, we help more than 2 million Australians to build a better financial future. With around $112 billion in funds under management, we focus on delivering strong long-term outcomes for our members — from their first job through to retirement. Your best at Rest means focusing on what matters, being trusted to get on with it, and knowing your work genuinely makes a difference. That’s how we operate every day, guided by our values: Be Daring, Keep It Simple, Take Action and Have Grit.Join us as an Application Security Analyst on an 18 Month Fixed Term Contract. This is your opportunity to make a real contribution to the financial wellbeing of millions of Australians.About the roleAt Rest, we're committed to helping our members achieve a better retirement. As our Application Security Analyst, you'll play a critical role in strengthening the security of our applications, APIs and software delivery practices.Working closely with engineering, architecture, product and technology teams, you'll lead application security initiatives, embed security into the development lifecycle, and provide pragmatic, risk-based guidance that supports secure delivery and innovation.What you'll doLead application security assessments across web applications, APIs and cloud-based services, identifying risks and recommending appropriate treatment plans.Partner with engineering and architecture teams to embed security into solution design through threat modelling and secure-by-design practices.Validate, prioritise and manage application security findings, providing risk-based remediation guidance and distinguishing genuine risks from false positives.Drive the effectiveness and continuous improvement of application security tooling, including SAST, DAST, SCA, API security testing and secrets detection.Promote secure SDLC and DevSecOps practices, integrating security controls into CI/CD pipelines and software delivery processes.Coordinate penetration testing activities, validate findings and oversee remediation outcomes.Develop and maintain application security standards, guardrails and secure development practices.Provide security guidance, education and enablement to developers, engineers and security champions.Support security incident investigations where application vulnerabilities or insecure design may be contributing factors.Deliver application security reporting, metrics and insights, highlighting emerging risks, remediation performance and overall security posture.

  • ID: #55334883
  • State: New Jersey Sydney 00000 Sydney USA
  • City: Sydney
  • Salary: USD TBD TBD
  • Job type: Full-time
  • Showed: 2026-09-16
  • Deadline: 2026-11-15
  • Category: Et cetera
Apply